The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 23, 2024

Filed:

Jan. 10, 2022
Applicant:

Check Point Serverless Security Ltd., Tel Aviv, IL;

Inventors:

Ohad Tanami, Jerusalem, IL;

Itay Harush, Jerusalem, IL;

Piyush Anand Deshpande, Pune, IN;

Devdatta Krishna Deshpande, Pune, IN;

Assignee:
Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/54 (2013.01); G06F 9/50 (2006.01); G06F 21/55 (2013.01); G06F 21/60 (2013.01);
U.S. Cl.
CPC ...
G06F 21/54 (2013.01); G06F 9/5016 (2013.01); G06F 9/5038 (2013.01); G06F 9/505 (2013.01); G06F 21/554 (2013.01); G06F 21/604 (2013.01);
Abstract

A protection system is provided for delivering runtime security to a task including a workload container. The protection system uses a sidecar to limit access of the workload container to a standard library of the operating system running the workload container by modifying the task so that the sidecar is executed before the workload container. The sidecar places a guard loader into a shared volume and binds the workload container, such that calls to the workload container are passed to an agent binary. The agent binary compares requested calls from the workload container to a policy to approve and/or deny the requested calls. If the requested call is approved, then the requested call is passed to the standard library.


Find Patent Forward Citations

Loading…